Cointime

Download App
iOS & Android

Logic flaw: Analysis of the DEUS attack incident

On May 6, 2023, Beijing time, a burn logic flaw was discovered in DEUS’s stablecoin DEI contract, resulting in an attacker gaining approximately $6.3 million in profits.

SharkTeam conducted a technical analysis of the incident and has summarized security measures as a precautionary lesson for future projects, aiming to strengthen the security defenses of the blockchain industry.

Analysis of the Incident

Attacker address:

0x08e80ecb146dc0b835cf3d6c48da97556998f599

Attack contract: 0x2b1a7a457a2c55ba1e03c087cc3e4e5b05b6360f

Vulnerable contract:

0xDE1E704dae0B4051e80DAbB26ab6ad6c12262DA0

Attack transactions:

0xde2c8718a9efd8db0eaf9d8141089a22a89bca7d1415d04c05ba107dc1a190c3

The execution flow of the attack transaction:

1. First, the attacker (0x08e80ecb) calls the attack function of the attack contract (0x2b1a7a45).

2. In the attack function, call the approve->burnFrom->transferFrom function of the vulnerable contract (0xDE1E704d)

3. In the transferFrom function, transfer 1.1 million DEI to your own account, and finally call the swap of the trading pair to exchange DEI for USD and transfer it to the attacker (0x08e80ecb).

Vulnerability analysis:

In the burnFrom function, the allowance of the sender to the account and the allowance of the account to the sender are copied directly.

The attacker first approves the maximum value of the vulnerable contract (0xDE1E704d), and then calls the burnFrom function to input amount=0, that is, directly makes the vulnerable contract (0xDE1E704d) approve the maximum value of the attack contract.

Then directly call the tranferFrom function to transfer 1.1 million DEI to your own address, and finally exchange it into USD through the pair transaction to complete the attack

Vulnerability Summary:

The root cause of this incident lies in a contract vulnerability (RouteProcessor2) related to the invocation permissions of the burnFrom function or a potential error in the _allowance parameter. It is necessary to make modifications based on the actual business requirements of the project. This can be addressed by setting appropriate administrative permissions for burnFrom or by adjusting the _allowance[_msgSender()][account] to _allowance[account][_msgSender()] or similar approaches for fixing the issue.

Security Recommendations:

In light of the recent attack incident, it is important to adhere to the following considerations during the development process:

1. Exercise caution and ensure the rigor of business logic when developing functions related to assets.

2. The vulnerable burnFrom function was introduced during a contract upgrade conducted by the project team on April 16. Therefore, before deploying or upgrading contracts, it is crucial for projects to undergo contract audits by professional third-party auditing teams.

About us

SharkTeam’s vision is to comprehensively protect the security of the Web3 world. The team is composed of experienced security professionals and senior researchers from all over the world. They are proficient in the underlying theory of blockchain and smart contracts, and provide services including smart contract auditing, on-chain analysis, and emergency response. It has established long-term cooperative relationships with key players in various fields of the blockchain ecosystem, such as Polkadot, Moonbeam, polygon, OKC, Huobi Global, imToken, ChainIDE, etc.Official
 website: https://www.sharkteam.org/
Twitter: https://twitter.com/sharkteamorg
Discord: https://discord.gg/jGH9xXCjDZ
Telegram: https://t.me/sharkteamorg

Comments

All Comments

Recommended for you

  • 38,244.04 DMD Permanently Burned in the Past 7 Days

    On June 25, 2026, the latest on-chain data from DMDAO revealed that a total of 38,244.04 DMD has been permanently burned through the established transaction and wealth management burn mechanisms over the past 7 calendar days.

  • BTC Falls Below $60,000

    Market data shows that BTC has fallen below $60,000, currently priced at $59,954.84, with a 24-hour decline of 4.19%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Drops Below $1600

    Market data shows that ETH has fallen below $1600, currently priced at $1597.55, with a 24-hour decline of 3.81%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Billionaire Philippe Laffont Prefers Investing in Space Over Bitcoin

    Philippe Laffont, founder and portfolio manager of Coatue Management, stated on the Squawk Box program that he is currently unable to determine his stance on Bitcoin. He mentioned that he is rethinking Bitcoin's positioning and expressed a preference for investing in space over Bitcoin. (thestreet)

  • Tech Giants' Data Center Leasing Commitments Exceed $850 Billion

    On June 24, an analysis by Bloomberg of regulatory filings revealed that as tech giants compete to expand their server clusters, the total amount of future data center leasing commitments by large cloud computing companies has continued to rise over the past year, surpassing $850 billion. Last quarter, Meta added leasing commitments of $79 billion, a 76% increase from the previous period; as of March 31, the total reached $182.9 billion. Meta CEO Mark Zuckerberg has stated that the company plans to invest hundreds of billions of dollars in AI infrastructure by 2030. Microsoft followed closely, adding over $41 billion in leasing commitments, bringing its total to $196.6 billion.

  • Address with $34.61 Million Long Position in 21,000 ETH Faces $1.696 Million Loss at 18x Leverage

    According to on-chain analyst Ai Yi, a certain address took a long position of 21,000 ETH with 18x leverage yesterday, amounting to approximately $34.61 million. Currently, it is facing an unrealized loss of $1.696 million, with an opening price of $1,728.5 and a liquidation price of $1,590.1.

  • U.S. 10-Year Treasury Yield Falls to 4.4138%, Lowest Since May 11

    On June 24, the yield on U.S. 10-year Treasury bonds fell to 4.4138%, the lowest level since May 11. The yield on U.S. 30-year Treasury bonds dropped to 4.8572%, the lowest since April 15.

  • Crypto Market Liquidations Reach $134 Million in the Last Hour, with $125 Million in Long Liquidations

    According to CoinGlass data, the total liquidation amount across the network in the last hour reached $134 million, with long liquidations accounting for $125 million and short liquidations amounting to $8.539 million.

  • BTC Falls Below $61,000

    Market data shows that BTC has fallen below $61,000, currently priced at $60,986.03, with a 24-hour decline of 2.88%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Web3 data and AI company Validation Cloud completes $10 million in new round of financing

     Web3 data and AI company Validation Cloud announced a $10 million financing round from True Global Ventures. The company plans to use the funds to expand its AI products and achieve seamless access to Web3 data.